WordPress 7.0.4 addressed a security vulnerability on certain installations using Imagick and Ghostscript. This article explains that August 2026 advisory and a practical update-verification process. It is not a recommendation to install an old release over a newer, supported version.
Reviewed September 13, 2026: The original release date was August 12. Check the current WordPress releases and your site’s update screen before choosing an upgrade path. Do not downgrade a newer secure installation to 7.0.4 to follow this historical article.
What the Official Advisory Confirmed
The WordPress 7.0.4 release announcement describes an authenticated remote code execution issue involving malicious file uploads. The security advisory for CVE-2026-65640 identifies two prerequisites: the server uses Imagick and Ghostscript, and an attacker has an account with the ability to upload files, such as an Author-level account.
The advisory rates the issue High, with a CVSS score of 8.8. For the 7.0 branch, it lists 7.0.0 through 7.0.3 as affected and 7.0.4 as patched. Other branches have their own affected and patched versions, listed in the advisory. This is not a claim that every anonymous visitor could exploit every WordPress website.
Check the Site, Not Just the Article’s Version Number
Record the installed WordPress version, the available update, and who manages the hosting account. If you do not know whether the server uses the affected image-processing components, ask the host or maintainer. Do not upload suspicious files to a production site to test the vulnerability.
WordPress recommends staying on its latest release. Its update instructions cover backups, automatic updates, the dashboard update process, and troubleshooting. A maintained installation needs a compatible update path, not a permanent exception because one old branch received a backported fix.
Use One Update and Recovery Checklist
- Identify responsibility. Decide who approves the change, who performs it, and who can restore the site. Confirm that the required hosting and administrative access works.
- Prepare a recoverable backup. Include the database, uploaded media, application files, and relevant configuration. Record its timestamp and restore location, and confirm the recovery procedure with the maintainer.
- Protect changing business data. On an active store or booking site, decide how new transactions will be preserved if recovery is needed. Restoring an earlier database can otherwise discard later orders.
- Check compatibility promptly. Use a controlled staging environment when available, keeping real email and payment actions disabled. Do not turn staging into an indefinite reason to leave a known vulnerability unaddressed.
- Apply the appropriate current update. In WordPress, use Dashboard > Updates and the offered update action, or have your maintainer follow the official procedure. Verify the installed version afterward.
- Test the customer journey. Run the checks below, inspect relevant error logs, and record any failure with its time and reproduction steps.
- Close the change record. Note the final version, backup reference, tests, remaining issues, and person responsible for follow-up.
Record Outcomes, Not Just “Site Looks Fine”
The following is a blank verification worksheet, not a claim that we tested your website or that a particular installation is secure. Adapt it to the features the business actually uses.
| Check | Expected outcome | Evidence to record |
|---|---|---|
| Installed version | The intended update completed | Version and completion time |
| Public pages and navigation | Important pages load and links reach the right content | URLs and browser/device used |
| Contact inquiry | A labeled test reaches the intended inbox or CRM | Test reference and delivery confirmation |
| Checkout or booking | The approved test completes without a live charge or real reservation | Test-mode reference and observed status |
| Staff access | Authorized staff can complete their normal work | Role tested, without recording credentials |
| Error monitoring | No new unresolved errors in the tested workflows | Relevant time window and follow-up ticket |
What If the Update Fails?
Capture the error and contact the host or maintainer rather than repeatedly changing unrelated settings. If recovery is necessary, agree how to preserve new orders and inquiries first. Restoring an affected version restores its security exposure too; any rollback needs a prompt remediation plan, not an assumption that the backup has solved the vulnerability.
Does an Automatic Update Finish the Job?
No. Automatic installation can reduce manual work, but someone still needs to confirm the resulting version and check the business workflows. An update notification is not evidence that a contact form delivers, a payment integration works, or unauthorized accounts are absent.
Get Help With a Controlled Update
Supreme Line can scope WordPress maintenance and update verification around your site’s forms, accounts, bookings, or store. Begin with the installed version and the problem you are seeing. Arrange access securely; do not send passwords in a general inquiry.



